Demodesk integrates Microsoft 365 SSO via OAuth 2.0. It’s enabled automatically when you register or sign in using “Sign in with Microsoft.”
After the first employee signs up, your IT team can see and manage the app in the Microsoft Entra admin center under Enterprise applications → Demodesk.
What we ask for and why
We request delegated (user-level) permissions so Demodesk only acts on behalf of the signed‑in user.
OpenID scopes
emailoffline_access(used to refresh tokens without repeated login)openidprofile
Microsoft Graph scopes
Calendars.ReadWrite: To view and create calendar eventsMail.Send: To send emails (confirmations, reminders, etc.) for scheduling.OnlineMeetings.ReadWrite: To read the Microsoft Teams meetings context and be able to schedule meetings (for scheduling).OnlineMeetingArtifact.Read.All: To access meeting artifacts (e.g., recordings)User.Read: To identify the user
Revoking access
Access can be revoked at any time:
From your Demodesk account (Connections settings)
Directly from your Microsoft/Outlook account
Access ends immediately upon disconnection.
How to enable SSO
1. Go to the Demodesk login page and choose “Sign in with Microsoft.”
2. Review and accept the requested permissions.
3. Demodesk should appear as app in Entra under "Enterprise apps"
To make your workspace SSO-only, admins can enable this directly in company settings:
Go to Settings > Company > Profile.
Under Sign-in, enable Require Google or Microsoft sign-in (disable email/password login).
Click Save.
Important: Users without a connected Google or Microsoft account will lose access. Make sure all users have linked their account before enabling this setting. The email and password fields remain visible on the login page, but users will see an error if they try to sign in that way.
Troubleshooting: "Need admin approval"
In many organizations, Microsoft requires a company administrator to approve Demodesk once for the whole organization before anyone can sign in. Until that is done, employees who choose "Sign in with Microsoft" will see a "Need admin approval" message and cannot continue. This is a Microsoft setting on your side, not a Demodesk error.
To resolve it, a Microsoft Entra administrator needs to grant admin consent for the whole organization:
Sign in to the Microsoft Entra admin center (entra.microsoft.com) as an administrator.
Go to Enterprise applications → Demodesk → Permissions.
Click "Grant admin consent for [your organization]" and approve.
Once granted, the "Need admin approval" message disappears and all users can sign in with Microsoft.
Two things to check if it still does not work:
Approve for the organization, not just yourself. Signing in as an admin may connect only your own account while everyone else stays blocked. The step above grants access for the entire company.
Make sure your admin role is active. Some organizations keep admin roles inactive by default and require you to activate them (via Privileged Identity Management) before use. If you hold an admin role but the approval keeps failing or looping back to "Need admin approval," activate your role (for example Privileged Role Administrator or Global Administrator) first, then grant consent again in the same session.
Demodesk requests only delegated (user-level) permissions, so a Cloud Application Administrator or Application Administrator role is sufficient to grant consent.
FAQs
Q: Does Demodesk see all calendars?
A: No. Only users who connect Microsoft 365, and only their default calendar.
Q: Are these permissions and behaviors different from Scheduling?
A: Yes. Scheduling may differ - see here for more details.
Q: Our users see "Need admin approval." Is something wrong with Demodesk?
A: No. Your organization requires an admin to approve Demodesk once for the whole company. See "Troubleshooting: Need admin approval" above.
